Latest CVE Feed
-
5.5
MEDIUMCVE-2023-26387
Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Expl... Read more
- Published: Apr. 12, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-29573
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.... Read more
Affected Products : bento4- Published: Apr. 13, 2023
- Modified: Feb. 07, 2025
-
5.5
MEDIUMCVE-2023-28085
An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials... Read more
Affected Products : oneview_global_dashboard- Published: Apr. 14, 2023
- Modified: Feb. 06, 2025
-
5.5
MEDIUMCVE-2023-28091
HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dump... Read more
- Published: Apr. 14, 2023
- Modified: Feb. 06, 2025
-
5.5
MEDIUMCVE-2024-56454
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Jan. 08, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2023-22307
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.... Read more
Affected Products : checkmk_appliance_firmware- Published: Apr. 18, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-2170
The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticate... Read more
Affected Products : taxopress- Published: Apr. 19, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-28087
An HPE OneView appliance dump may expose OneView user accounts... Read more
- Published: Apr. 25, 2023
- Modified: Feb. 03, 2025
-
5.5
MEDIUMCVE-2023-26930
Buffer Overflow vulnerability found in XPDF v.4.04 allows an attacker to cause a Denial of Service via the PDFDoc malloc in the pdftotext.cc function. NOTE: Vendor states “it's an expected abort on out-of-memory error.”... Read more
Affected Products : xpdf- Published: Apr. 26, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-28477
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name parameter.... Read more
- Published: Apr. 28, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21495
Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.... Read more
- Published: May. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-38685
In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no additional execution privileges needed.... Read more
- Published: May. 09, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-44419
In modem, there is a possible missing verification of NAS Security Mode Command Replay Attacks in LTE. This could local denial of service with no additional execution privileges.... Read more
- Published: May. 09, 2023
- Modified: Jan. 28, 2025
-
5.5
MEDIUMCVE-2022-47487
In thermal service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service local denial of service with no additional execution privileges.... Read more
- Published: May. 09, 2023
- Modified: Jan. 28, 2025
-
5.5
MEDIUMCVE-2022-48233
In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .... Read more
- Published: May. 09, 2023
- Modified: Jan. 28, 2025
-
5.5
MEDIUMCVE-2022-48370
In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.... Read more
- Published: May. 09, 2023
- Modified: Jan. 28, 2025
-
5.5
MEDIUMCVE-2022-48371
In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.... Read more
- Published: May. 09, 2023
- Modified: Jan. 28, 2025
-
5.5
MEDIUMCVE-2022-48376
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.... Read more
- Published: May. 09, 2023
- Modified: Jan. 28, 2025
-
5.5
MEDIUMCVE-2022-48379
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.... Read more
- Published: May. 09, 2023
- Modified: Jan. 28, 2025
-
5.5
MEDIUMCVE-2023-30088
An issue found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_execute function in mjs.c.... Read more
Affected Products : mjs- Published: May. 09, 2023
- Modified: Jan. 29, 2025